[Date Prev][Date Next]
[Chronological]
[Thread]
[Top]
Antw: Re: Issues with Ppolicy Overlay and chaining (master/slave)
- To: "Raul Hernandez" <hernandezr@gmail.com>, <openldap-technical@openldap.org>
- Subject: Antw: Re: Issues with Ppolicy Overlay and chaining (master/slave)
- From: "Ulrich Windl" <Ulrich.Windl@rz.uni-regensburg.de>
- Date: Thu, 18 Sep 2014 08:42:47 +0200
- Content-disposition: inline
- In-reply-to: <CAL3GdwNJfDBDvwHmxFntggndsRC=wZ+SHM0LVeBbYQEm3ZGaEw@mail.gmail.com>
- References: <CAL3GdwNiuufEsL=dvDWYHtB4sNWOrV5Tpwn+gdGwkLLHzBJadQ@mail.gmail.com> <F2FE0D5F022240BE75E33330@192.168.1.61> <CAL3GdwN_iZzLEGY_miUz58QXDfkC22u+5CKcUbk5CSVFrW=hUQ@mail.gmail.com> <0E4107FA3A51F68D8FC37981@192.168.1.61> <CAL3GdwNJfDBDvwHmxFntggndsRC=wZ+SHM0LVeBbYQEm3ZGaEw@mail.gmail.com>
>>> Raul Hernandez <hernandezr@gmail.com> schrieb am 16.09.2014 um 23:36 in
Nachricht
<CAL3GdwNJfDBDvwHmxFntggndsRC=wZ+SHM0LVeBbYQEm3ZGaEw@mail.gmail.com>:
[...]
> the my HDB access configuration, and realize that my chaining
> (cn=syncrepluser,ou=security,dc=example,dc=com) user had "write"
> permissions on userPassword, pwdFailuretime, pwdChangedTime, pwdHistory,
> pwdAccountLockedTime attributes and that wasn't enough. I changed the
> "write" permission to "manage" and everything started working.
[...]
I read the slapd.access manual page, aand could not get it:
--
The level access model relies on an incremental interpretation of the
access privileges. The possible levels are none, disclose, auth, com-
pare, search, read, write, and manage. Each access level implies all
the preceding ones, thus manage grants all access including administra-
tive access. The write access is actually the combination of add and
delete, which respectively restrict the write privilege to add or
delete the specified <what>.
--
"administrative access" is nowhere explained. So what does "manage" allow that "write" does not?
Regards,
Ulrich